top of page

AI Law Imperative: Why the World Needs Laws to Regulate Artificial Intelligence

Writer: Manoj Ambat
Manoj Ambat
1 day ago
26 min read

Artificial intelligence is no longer merely another technological development waiting to be absorbed into existing legal systems. It has become a technological infrastructure capable of generating text, images, audio and video; analysing enormous quantities of information; writing and modifying software; making recommendations; interacting with digital systems; and increasingly performing complex tasks with limited human intervention. The speed of this development is itself becoming a legal problem. AI capabilities are advancing faster than many regulatory systems can study, classify and respond to them. The United Nations' emerging international AI-governance architecture recognises precisely this gap, noting that AI capabilities are advancing faster than governance frameworks can keep pace. The first United Nations Global Dialogue on AI Governance was held in Geneva on 6–7 July 2026, bringing governments and other stakeholders together to address the challenge.


Watch the complete podcast

The question confronting the international legal order is therefore no longer simply whether artificial intelligence should be encouraged or restricted. The more fundamental issue is whether existing law can govern a technology capable of imitating human communication, generating apparently authentic but entirely synthetic material, making decisions at machine speed, operating across borders and, through agentic systems, initiating sequences of actions with limited immediate human intervention. Traditional law generally regulates human beings, corporations, institutions and identifiable acts. AI introduces something different: technological systems capable of producing consequential outputs without possessing the legal personality or moral responsibility traditionally associated with human actors.


That gap between capability and accountability is becoming one of the central legal questions of the twenty-first century.


AI Is Developing Faster Than the Law


Technological change has always challenged the law. The automobile produced traffic regulation; aviation produced international safety regimes; broadcasting required new communications rules; and the internet generated an enormous body of cyber, privacy, intellectual-property and intermediary law. Artificial intelligence presents a more difficult regulatory challenge because it is not confined to one sector. It is a general-purpose capability capable of entering almost every sector simultaneously.


The same underlying technologies can be deployed in medicine, education, banking, defence, policing, journalism, entertainment, employment, scientific research, courts and government administration. Consequently, a rule designed around one application may become inadequate when the same capability is deployed elsewhere. An AI system recommending a film presents an entirely different level of risk from one assessing a person's creditworthiness; a system drafting correspondence raises different concerns from one controlling critical infrastructure; and an AI tool assisting legal research presents a different question from a system generating material later submitted as evidence.


Contemporary AI governance is therefore increasingly concerned with risk, context and use rather than technology alone.


The European Union's AI Act provides one of the clearest examples. It establishes a risk-based architecture distinguishing prohibited practices, high-risk systems and transparency obligations. From 2 August 2026, significant provisions became applicable, including enforcement powers, obligations concerning general-purpose AI and transparency requirements for certain AI systems. The framework also requires certain AI-generated content, including deepfakes, to be identifiable.


The significance of the European approach is not simply that Europe has enacted an AI statute. It demonstrates an attempt to construct a general legal architecture for a general-purpose technology.


Other jurisdictions have taken markedly different approaches.


China has developed rules covering recommendation algorithms, deep synthesis and generative AI. Its 2025 rules on the identification of AI-generated and synthetic content require explicit and implicit identification mechanisms, including information embedded in file metadata, while imposing obligations on providers and content-distribution services. The rules took effect on 1 September 2025.


South Korea's AI Basic Act entered into force on 22 January 2026, creating a national framework for AI development and adoption alongside obligations concerning safety, transparency and high-impact and generative AI.


Japan has also enacted dedicated AI legislation. Its 2025 law concerning the promotion of research, development and utilisation of AI-related technologies establishes basic principles, national responsibilities, an AI Basic Plan and an AI Strategic Headquarters, creating a national framework that differs considerably from the European model.


The United Kingdom has instead adopted a substantially principles-based, regulator-led approach. Its framework identifies five cross-sector principles: safety and robustness; transparency and explainability; fairness; accountability and governance; and contestability and redress. The UK deliberately favoured an agile and iterative model rather than initially imposing a single comprehensive statutory framework.


The United States presents another model. In March 2026, the White House published a national AI legislative framework containing recommendations for federal AI legislation. The American system remains considerably more decentralised than the EU approach, with federal policy, sectoral regulation, existing law and state-level initiatives operating alongside one another.


India has followed a further path. Its India AI Governance Guidelines, released in November 2025, establish seven guiding principles and a broader framework based on risk, accountability, safety, fairness and human-centricity. The guidelines recommend reviewing existing law, making targeted legislative amendments where necessary, developing common standards for issues such as content authentication and data integrity, creating regulatory sandboxes and continuously monitoring emerging risks. The Government subsequently established the AI Governance and Economic Group as an institutional mechanism for coordinating national AI governance.


Australia is moving from voluntary guardrails toward consideration of mandatory safeguards for AI used in high-risk settings. Its proposed framework identifies risks involving legal rights, safety, collective interests, the economy, society, the environment and the rule of law. Existing voluntary guardrails already emphasise accountability, risk management, data provenance, testing, human control, disclosure and the ability of affected persons to challenge AI outcomes.


Brazil has also moved toward a dedicated legislative framework. Its Senate approved Bill PL 2338/2023, a proposed legal framework for artificial intelligence, before transmitting it to the Chamber of Deputies in March 2025. The proposal addresses AI use, civil liability and individual and collective rights.


These approaches are not identical, nor should they necessarily be. They reflect different constitutional structures, economies, technological capabilities, regulatory philosophies and social priorities. What they demonstrate, however, is that AI governance has moved from theoretical ethics into legislation, regulation and public administration.


The Legal Problem Is Bigger Than AI Hallucinations


One of the most visible AI-related legal problems is hallucination. A generative AI system can produce a citation to a case that does not exist, attribute a paragraph to a judgment that never contained it, or generate a historical fact, scientific reference or quotation that appears authentic but is entirely fabricated.


The consequences become particularly serious in law because legal systems depend upon authoritative sources. A fabricated case is not simply misinformation: when a lawyer places it before a court, it can contaminate legal reasoning; when a tribunal relies upon it, the problem becomes institutional.


This problem has already reached the Supreme Court of India. In Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd., 2026 INSC 668, the Court dealt with AI-generated legal citations that were found to be non-existent or attributed with paragraphs that did not exist. It set aside the decisions affected by reliance on the fabricated material and emphasised the need for human control over AI-assisted adjudication.


The case illustrates a broader principle: the more authoritative the environment in which AI is used, the greater the requirement for independent verification.


The same principle extends beyond courts. AI-generated medical advice, financial recommendations, security assessments and government decisions may all have serious consequences. The technology can produce information at extraordinary speed; the law must determine who is responsible for deciding whether that information can be trusted.


Synthetic Reality and the Problem of Artificial Evidence


Perhaps the most profound legal challenge created by generative AI concerns evidence.

For much of legal history, courts developed methods for determining whether evidence was genuine. Witnesses testified, documents were examined, signatures compared and photographs or recordings assessed as representations of events. Digital technology already complicated those assumptions; generative AI complicates them further.


A photograph can now be generated without a camera ever recording the depicted event. A voice can be synthetically produced without the speaker saying the words. A video can show a person doing something that never happened. A document can reproduce the appearance of an authentic institutional record without ever having been issued by that institution.


The legal system is therefore approaching an era in which appearance can no longer automatically establish authenticity.


The questions increasingly concern provenance: Where did the file originate? Who created it? What system generated it? What metadata does it contain? Has it been altered? Can its chain of custody be established? Can independent forensic examination verify it? Was it generated or materially altered by AI, and was that fact disclosed?

China's 2025 rules on AI-generated synthetic content are particularly relevant because they require visible and hidden identification mechanisms and impose obligations concerning metadata and content dissemination. The European Union's AI Act likewise contains transparency obligations concerning AI-generated and manipulated content, including deepfakes.


These developments point toward a future in which content provenance may become as legally important as content itself.


Deepfakes: When Seeing Is No Longer Believing


Deepfakes demonstrate why AI regulation cannot be confined to the technology industry.


A convincing synthetic video can damage a person's reputation, interfere with an election, create false evidence, manipulate financial markets, trigger public disorder or facilitate extortion. A cloned voice can impersonate a family member, business executive, lawyer, public official or financial officer.


Traditional criminal and civil laws can address many of these acts. Fraud, impersonation, defamation, forgery, privacy violations and related offences do not disappear simply because AI was used. Yet existing law may not always provide the technological mechanisms necessary to establish provenance, identify the source rapidly or contain the resulting harm.


Who must identify synthetic material? What duty does the AI provider have? When should a platform be required to act? What remedy should be available to a victim? What happens when the provider, user, platform and victim are located in different countries?

These are not merely technical questions. They are questions of legal responsibility.


Autonomous AI and the Problem of the Legal Actor


The next stage may be even more complicated.


Generative AI primarily responds to human instructions. Increasingly, however, AI systems are being developed as agents capable of planning tasks, using software tools, retrieving information, communicating with other systems and taking sequential actions with limited intervention.


That introduces a difficult legal question: what happens when an AI agent performs an action with legal consequences?


Suppose an AI agent enters into a transaction, sends a communication that creates a contractual commitment, makes a financial transaction causing loss, or accesses a computer system and causes damage. Is the developer responsible, the deployer, the user, the owner of the infrastructure—or some combination of them?


Traditional law is generally built around identifiable actors. AI agents challenge the assumption that the person initiating an action is necessarily the person, or legal entity, actually responsible for every intermediate step.


This does not necessarily mean that AI should be recognised as a legal person. Granting legal personality to an AI system could instead create a mechanism for transferring liability away from the human or corporate actors who designed, deployed or controlled it.


The immediate legal question is more practical:


How should responsibility be allocated when an autonomous or semi-autonomous AI system produces a legally significant outcome?


That question deserves dedicated legal treatment.


The Accountability Gap


Every legal system ultimately depends upon accountability. Someone must answer for unlawful conduct, compensate a victim, correct an error or face regulatory consequences.


AI creates the possibility of an accountability gap in which responsibility becomes distributed across a chain of actors. A model developer may argue that the system was misused; a deployer may contend that it behaved unexpectedly; a user may argue that the system acted autonomously; and a platform may say that it merely provided access.

Meanwhile, the person harmed by the system is left with the most basic legal question:


Who is responsible?


Future AI liability frameworks will therefore have to look beyond a simple developer-versus-user model. Responsibility may need to be allocated across the AI supply chain according to factors such as control, foreseeability, risk, deployment decisions and actual involvement.


Australia's proposed mandatory guardrails for high-risk AI are already moving in this direction by considering responsibilities across developers and deployers and emphasising risk management, human oversight and accountability.


AI in Courts: The Legal Profession's First Warning


The courtroom provides perhaps the clearest demonstration of why AI governance matters.


AI can dramatically accelerate legal research, document review and case management. Yet the use of such systems does not transfer professional responsibility from the lawyer or judicial responsibility from the court. Authorities must still be verified, evidence authenticated and judicial reasoning independently undertaken.


The Indian Supreme Court's experience offers an important warning. A system capable of generating a convincing legal citation is not necessarily capable of establishing that the cited authority exists. Consequently, AI may assist legal reasoning, but it cannot become an unverified source of legal authority.


The same principle applies to evidence. A court cannot assume that a video is genuine merely because it looks authentic, or that an audio recording is genuine because it sounds authentic. The courtroom of the AI era will increasingly become a contest not merely over what evidence says, but over whether the evidence is real.


AI and the Human Right to Know


Another important issue is transparency.


If a government agency uses AI to determine whether an individual receives a benefit, licence or public service, should the individual know? If an employer uses AI in recruitment, should an applicant be informed? If a bank relies upon an automated system to assess creditworthiness, should the customer be able to challenge the decision? And if a court employs AI-assisted research, what degree of transparency is appropriate?


The answers will differ according to context, but an increasingly important principle is that people affected by consequential AI decisions should have meaningful avenues for explanation, challenge and redress.


The UK's framework includes contestability and redress among its core regulatory principles. Australia's emerging approach similarly emphasises accountability, human control and the ability of affected persons to challenge AI outcomes.


This raises a fundamental procedural question:


Can a person meaningfully challenge a decision if they do not know how AI contributed to it?


Why National Laws Alone May Not Be Enough


AI is global by design.

A model can be developed in one country, trained using data originating from many countries, operated through infrastructure elsewhere and used by someone thousands of kilometres away. A deepfake can be generated in one jurisdiction, uploaded through a platform incorporated in another and viewed by millions in a third. An AI-enabled cyberattack can cross several borders before authorities identify its source.


This creates the possibility of regulatory arbitrage.


If one country establishes strict AI rules while another offers an almost unregulated environment, developers, users or malicious actors may shift activity toward the less restrictive jurisdiction. The international community has encountered similar problems in cybercrime, money laundering, aviation, maritime safety and environmental protection.

AI may require another layer of international cooperation—not necessarily one global AI statute or identical national laws, but common minimum principles, interoperable standards and mechanisms for cross-border cooperation.


The United Nations has already recognised this need. The Global Digital Compact calls for international cooperation to promote coordination and compatibility among emerging AI governance frameworks and identifies transparency, accountability and robust human oversight as important elements of international AI governance.


In August 2025, the UN General Assembly established an Independent International Scientific Panel on AI and a Global Dialogue on AI Governance. The first Global Dialogue was held in Geneva in July 2026, creating an international platform for governments and stakeholders to develop common approaches.


The institutional development is significant. The world is beginning to construct the machinery for international AI governance. The unresolved question is how far that machinery should ultimately go.


What Should an International AI Governance Framework Address?


There is no compelling reason for every country to adopt identical legislation. Different jurisdictions will inevitably make different choices according to their constitutional structures, economies and social priorities. What is more realistic is a set of common principles around which national systems can be built.


Human accountability should be fundamental. AI must not become a mechanism through which legal responsibility disappears.


Transparency should accompany consequential use, particularly where individuals may be materially affected by an AI system.


Synthetic-content identification should help distinguish AI-generated or materially manipulated material from authentic records where that distinction matters.


Evidence integrity should receive particular attention, with courts developing rules and technological standards capable of establishing the provenance of AI-generated or AI-manipulated material.


Risk-based regulation should distinguish ordinary low-risk applications from systems capable of affecting liberty, health, finances, employment, public safety or fundamental rights.


Meaningful human oversight should accompany high-impact AI, with responsibility remaining identifiable even where systems operate with considerable autonomy.


Testing and incident reporting may be necessary for high-risk systems, allowing regulators to identify systemic failures rather than learning only after serious harm occurs.


Rights of challenge and redress should protect individuals affected by consequential AI decisions.


Cross-border cooperation will be necessary because AI-related harm can occur simultaneously across multiple jurisdictions.


Finally, the framework must be adaptable.


That last principle may ultimately prove the most important.


AI Law Cannot Become Obsolete Law


A conventional statute can take years to draft, debate, amend and implement. AI capabilities can change substantially within months.


This creates a structural problem. If legislation attempts to describe every technological feature of artificial intelligence, it may become obsolete almost immediately. If legislation is too general, however, it may fail to provide meaningful safeguards.


The answer may lie in a layered architecture: primary legislation establishes fundamental principles, rights, duties, prohibited conduct, liability rules and institutional authority; regulators develop technical standards that can evolve more rapidly; standards bodies establish interoperability and provenance requirements; independent experts periodically assess emerging risks; regulatory sandboxes permit controlled experimentation; and incident databases allow regulators to learn from failures.


India's AI Governance Guidelines reflect elements of this approach. They recommend agile and principle-based governance, common standards, regulatory sandboxes, continuous review and horizon scanning while recognising that existing laws may need amendment as capabilities and risks evolve.


The UK's approach similarly emphasises agility and iteration because AI is developing rapidly.


The emerging lesson is that AI law should establish durable legal principles and responsibilities while allowing technical governance to evolve at the pace of technology.

Should Every Country Enact a Comprehensive AI Act?


This is where the international debate becomes more nuanced.


There is a strong case for dedicated legislation. A comprehensive AI statute can create clarity, define high-risk systems, allocate responsibilities, establish regulators and provide coherent rules for liability, transparency and redress. The EU and South Korea demonstrate that such legislation is possible, while Japan has created its own statutory and strategic model.


There is also a legitimate counterargument. A technology developing as rapidly as AI may be poorly served by rigid legislation, while existing laws concerning privacy, consumer protection, competition, intellectual property, criminal conduct and cybersecurity already regulate many AI-related harms.


India's current approach illustrates this alternative. Its AI Governance Guidelines emphasise using existing legislation where possible while identifying areas where targeted amendments may be necessary.


The real question, therefore, is not whether every country should reproduce the EU AI Act. It is whether every country should ensure that its legal system contains clear, enforceable mechanisms capable of dealing with AI-specific risks that ordinary law cannot adequately address.


 

India: From AI Governance Guidelines to an AI Legal Framework


India presents an especially interesting case because it has not chosen to wait for a comprehensive AI statute before beginning to regulate the technology. The country has instead adopted what the Government describes as a balanced and pragmatic techno-legal approach, combining existing legislation, sectoral regulation, technological safeguards and the India AI Governance Guidelines. The Guidelines, released in November 2025, are based on seven principles: Trust, People First, Innovation over Restraint, Fairness and Equity, Accountability, Understandable by Design, and Safety, Resilience and Sustainability. The Government has also established the AI Governance and Economic Group as a high-level inter-ministerial body to coordinate national AI governance policy, while a Technology and Policy Expert Committee has been constituted to provide specialist advice on regulatory and technological questions.


This is an important foundation. It would therefore be inaccurate to suggest that India is waiting for an AI law before taking action. The more interesting question is whether the present architecture will remain sufficient as AI capabilities develop. The Government's current position is that a new horizontal AI law is not required at this stage and that existing laws, including the Information Technology Act, the Digital Personal Data Protection framework and sector-specific regulation, should continue to be used wherever possible. That may be a reasonable starting position for a rapidly developing technology. But it should not necessarily be treated as the final destination.


The legal challenge will change as AI moves from systems that merely generate content toward systems capable of making consequential decisions and taking increasingly autonomous actions. At that point, scattered provisions in existing legislation may leave important questions unanswered. India may therefore eventually require a dedicated Artificial Intelligence Governance and Accountability Act, not to replace existing laws but to provide an overarching legal architecture connecting them.


What an Indian AI Act Could Look Like


An Indian AI statute need not attempt to regulate every algorithm or every use of machine learning. Such an approach would quickly become obsolete. Instead, legislation should establish a technology-neutral framework based on risk, impact, accountability and human control.


The first principle should be human accountability. Every high-impact AI system deployed in India should have an identifiable legal person or organisation responsible for its deployment and governance. The fact that an AI system acted autonomously should not, by itself, create an accountability vacuum.


The second should be risk classification. AI systems should be classified according to the consequences of their use rather than simply according to their technical sophistication. Low-risk applications could remain subject to ordinary law and basic transparency requirements. High-impact systems used in healthcare, financial services, employment, policing, courts, critical infrastructure, education, defence or government welfare decisions should face enhanced obligations. The Indian AI Governance Guidelines already recommend a risk-based and proportionate approach and specifically recognise risks including bias, discrimination, unfair outcomes, exclusion, misinformation and deepfakes.


The third should be mandatory impact assessment for high-risk AI. Before deploying an AI system capable of materially affecting a person's rights, liberty, livelihood, finances, access to essential services or legal position, the deploying organisation should conduct an AI Impact Assessment addressing foreseeable risks, bias, data quality, cybersecurity, explainability, human oversight and available remedies.


The fourth should be human oversight. An AI system used in a high-impact context should not become the final and unreviewable decision-maker. Affected persons should have access to meaningful human review. This principle would be particularly important in areas such as welfare distribution, recruitment, lending, insurance, healthcare, policing and judicial administration.


The fifth should be algorithmic accountability and auditability. Organisations deploying high-risk AI should maintain appropriate records concerning the system's purpose, data sources, testing, known limitations, significant incidents and human oversight. Independent or regulator-directed audits should be possible where the risk justifies them. The objective would not be to force companies to reveal every proprietary element of their algorithms, but to ensure that regulators can establish whether a high-impact system is operating within legally acceptable parameters.

The sixth should be synthetic-content regulation. AI-generated or materially altered audio, video, images and other forms of content capable of misleading the public should, where appropriate, carry reliable disclosure and provenance mechanisms. This is an area where India has already begun regulatory development. MeitY has undertaken consultation concerning amendments to the IT Rules relating to synthetically generated information, while the broader AI governance framework recommends common standards for content authentication and data integrity.


The seventh should be special protection for artificial evidence. Indian evidence law will increasingly need to confront AI-generated photographs, audio, video, documents and other synthetic material. The law should provide a clear framework for disclosure, provenance, forensic verification and challenge where a party alleges that digital evidence has been generated or materially altered by AI.


The eighth should be AI-generated legal material. The experience of the Indian judiciary with hallucinated case law demonstrates why legal AI requires particular safeguards. AI-generated authorities should never be treated as authentic merely because they appear in a sophisticated legal research system. Lawyers, tribunals and courts should retain an independent duty to verify authorities before relying upon them.


The ninth should be rights of explanation and challenge. Where an AI system materially contributes to a decision affecting an individual, the person concerned should, subject to legitimate security and confidentiality exceptions, have a right to know that AI was used and a meaningful opportunity to challenge the decision before an appropriate human authority.

The tenth should be clear liability rules. An Indian AI law should establish principles for allocating liability among developers, deployers, operators and users according to control, foreseeability, negligence, statutory duties and the nature of the harm. It should prevent the use of AI autonomy as a convenient defence against responsibility.


AI and Indian Data Protection


Any Indian AI framework would also have to operate alongside data-protection law rather than in isolation.


AI systems frequently require enormous quantities of data for training, testing and operation. Some of that data may contain personal information, sensitive commercial information or confidential records. The Digital Personal Data Protection Act, 2023 therefore forms an important part of the existing legal environment in which AI is developed and deployed. Government material on India's AI governance architecture expressly identifies data protection, privacy, confidentiality and information security as relevant safeguards.


A future AI statute should therefore clarify the relationship between AI development and data-protection obligations. Questions concerning lawful processing, consent, purpose limitation, data security, retention, children's data and rights of individuals will increasingly intersect with AI training and deployment.


The objective should not be to prevent legitimate AI development through excessive restrictions on data. It should be to ensure that technological innovation does not turn personal information into an effectively unregulated resource.


AI and Indian Criminal Law

Criminal law presents another important frontier.

AI can facilitate fraud, impersonation, extortion, identity theft, cybercrime, creation of synthetic evidence, harassment and other offences. Many of these acts can already fall within existing criminal and information-technology legislation. The problem is not necessarily the absence of an offence for every AI-related act.


The more difficult question is whether existing offences adequately capture AI-specific modes of commission, particularly where autonomous systems, synthetic identities or automated agents are involved.


India's approach should therefore avoid creating dozens of narrowly defined AI offences that could become obsolete as technology changes. A better model may be to establish technology-neutral offences and aggravating circumstances where AI is deliberately used to facilitate serious unlawful conduct, while leaving room for courts to apply existing criminal law to emerging technological methods.


AI and the Indian Evidence System


Evidence may ultimately require one of the most significant adaptations.


The law must distinguish between an authentic digital record and a synthetic creation. This does not mean that AI-generated material should automatically be inadmissible. Synthetic material can itself become relevant evidence—for example, to demonstrate what a particular AI system generated or how a synthetic communication was created.

The crucial question is provenance.


A future Indian evidentiary framework could therefore distinguish among original digital evidence, digitally altered evidence, AI-generated evidence and evidence concerning the operation of an AI system. Each category could have appropriate requirements for disclosure, authentication and forensic examination.


The objective should be to prevent synthetic material from entering the courtroom under the false assumption that digital appearance equals factual authenticity.


AI and the Indian Legal Profession


The legal profession should also receive specific attention.


The Bar Council of India, judicial academies, law universities and professional bodies could develop binding or advisory standards concerning responsible use of generative AI by advocates, law firms and legal institutions. These could cover verification of authorities, confidentiality, client data, disclosure, professional responsibility and the use of AI in drafting pleadings.


The basic principle should be straightforward:


A lawyer may delegate drafting or research assistance to a machine, but cannot delegate professional responsibility to it.


That principle could become particularly important as AI becomes integrated into commercial legal research platforms and document-management systems.


A Dedicated AI Regulatory Authority?


India may eventually have to consider whether AI governance should remain distributed entirely among existing regulators or whether a dedicated coordinating authority is necessary.


The present institutional model already moves in the direction of coordination. The AIGEG provides high-level inter-ministerial coordination, while the TPEC provides expert technical and policy advice. The Government's AI Governance Guidelines also contemplate institutional mechanisms including an AI Safety Institute and continued involvement of sectoral regulators.


A future statute could preserve this distributed structure while creating a statutory National AI Governance Authority or equivalent coordinating mechanism if experience demonstrates that coordination gaps cannot otherwise be resolved.


Such an authority should not become a centralised licensing bureaucracy for every AI application. Its primary functions could instead include maintaining national AI-risk classifications, coordinating regulators, issuing technical standards, maintaining an AI incident registry, supervising high-risk systems where necessary, coordinating international cooperation and advising Parliament and government on emerging risks.


AI Regulatory Sandboxes


India should also make extensive use of regulatory sandboxes.


The India AI Governance Guidelines specifically recommend regulatory sandboxes for cutting-edge technologies, with testing conducted within controlled environments and accompanied by documentation of the systems tested, safeguards applied and risks identified.


This could be particularly valuable in healthcare, financial technology, agriculture, legal technology, public administration and autonomous systems.


A sandbox allows innovation to occur without forcing society to choose between unrestricted deployment and prohibition. Developers can experiment, regulators can observe, researchers can identify weaknesses and policymakers can gather evidence before imposing permanent rules.


For India, which seeks simultaneously to become an AI innovation centre and a responsible AI jurisdiction, this balance could be particularly important.


A Practical Indian Model


India therefore does not necessarily need to choose between doing nothing and immediately adopting an enormous comprehensive AI statute.


A practical progression could be:


Stage One: strengthen the existing AI Governance Guidelines, AIGEG, TPEC and technical safety institutions.

Stage Two: identify regulatory gaps through sectoral experience, judicial decisions, AI incidents and regulatory sandboxes.

Stage Three: amend existing laws where the problem can be solved effectively through targeted intervention.

Stage Four: enact an overarching AI Governance and Accountability Act when the accumulated evidence demonstrates that existing legislation and guidelines are no longer sufficient.

Stage Five: develop technical standards and subordinate regulations that can evolve considerably faster than primary legislation.


Such an approach would preserve India's present emphasis on innovation while creating a clear route toward stronger statutory governance if AI capabilities and risks continue to accelerate.


What India Should Aim For


India should not necessarily attempt to become the country with the most restrictive AI law.


Nor should it seek to replicate the regulatory architecture of another jurisdiction without considering India's own circumstances.


India needs a framework suited to a country with enormous linguistic diversity, a vast digital population, rapidly expanding digital public infrastructure, a large technology sector, a developing economy and significant differences in digital access and literacy.

The regulatory objective should therefore be safe scale.


India should be able to deploy AI across healthcare, agriculture, education, legal services, manufacturing, defence, public administration and scientific research while ensuring that high-impact applications remain accountable.


The seven principles already identified in India's AI Governance Guidelines provide a useful foundation. What may eventually be required is to convert some of those principles from policy guidance into enforceable legal rights and duties where experience demonstrates that voluntary or existing-law mechanisms are insufficient.


The future Indian model could therefore be described as:

Innovation by default. Regulation according to risk. Human accountability without exception.


That could allow India to avoid two opposite errors: regulating AI so rigidly that innovation is discouraged, or allowing technological development to outrun the legal safeguards necessary to protect citizens.


From Indian AI Governance to an International AI Legal Order


India's experience also illustrates why the global debate should not be framed as a choice between regulation and innovation.


India has chosen a pragmatic, principle-based approach and is building institutions around it. The EU has chosen comprehensive legislation. China has developed detailed rules around particular AI technologies and synthetic content. South Korea has enacted dedicated AI legislation. Japan has established its own statutory framework. The United Kingdom has preferred an agile principles-based model. Other countries are developing their own approaches.


The objective of international AI governance should therefore not be to force every jurisdiction into one legislative template.


Instead, countries could develop compatible legal architectures around a common set of minimum principles.


India can contribute to that process from its own experience: risk-based governance, technology neutrality, human-centricity, regulatory sandboxes, technical standards, content authentication, sectoral enforcement and adaptive regulation.


The question is no longer whether India needs to choose between innovation and regulation.


It is whether India can demonstrate that innovation and accountability can be built into the same legal architecture.


That may ultimately be India's most important contribution to the global AI-law debate.

 

The Case for a Common Global Baseline


Perhaps the most practical international objective lies between complete legal uniformity and complete regulatory independence.


Countries could retain their own systems while agreeing upon certain common principles. One jurisdiction might regulate AI in employment more strictly than another, while both could nevertheless recognise that AI-generated evidence requires reliable provenance, that serious AI incidents should be reportable, that high-impact applications require meaningful human oversight and that affected individuals need avenues for challenging consequential automated decisions.


Such principles could provide interoperability without eliminating national differences.


The UN's Global Digital Compact already points toward this model by calling for coordination and compatibility among emerging AI governance frameworks.


The first Global Dialogue on AI Governance in Geneva demonstrated that the conversation is already international. The UN reports that the 2026 Dialogue involved delegations from 163 countries and more than 3,000 participants, with the process intended to continue annually.


The international system is therefore moving toward a governance conversation. The next question is whether that conversation will eventually produce sufficiently concrete legal standards.


The AI Law Imperative


Artificial intelligence presents humanity with an unusual legal situation. The technology is being developed primarily by private actors, deployed globally and evolving at extraordinary speed, while its consequences increasingly affect the public.


That creates a familiar legal principle in a new technological environment:

Power creates responsibility.


If an AI system can influence employment, finance, healthcare, information, evidence, security or government decisions, the law must be capable of identifying who is responsible for its design, deployment and consequences.


The objective of AI regulation should not necessarily be to prevent innovation, nor should regulation assume that every AI system is dangerous. The challenge is to distinguish useful innovation from unacceptable risk and construct safeguards proportionate to the consequences of failure.


The emerging international landscape offers several different answers. The European Union has constructed a comprehensive risk-based statutory framework; China has developed detailed administrative rules including synthetic-content regulation; South Korea has created a dedicated AI statute; Japan has established a national legislative and strategic framework; the United Kingdom has pursued principles-based regulation; the United States is developing federal legislative policy within a more decentralised system; India is experimenting with a techno-legal, principle-based model; Australia is considering mandatory safeguards for high-risk AI; Brazil is developing a dedicated statutory framework; and the United Nations has begun building institutions specifically concerned with global AI governance.


The world is therefore no longer debating whether AI governance is necessary in the abstract.


It is already experimenting with different forms of it.


The Question Is No Longer Whether AI Will Change the Law


The deeper historical significance of artificial intelligence may ultimately be understood not merely through what AI can do, but through what its arrival forces law to reconsider.

What constitutes evidence?


What constitutes authorship?


Who is responsible for an automated decision?


What constitutes consent when a person's face or voice can be reproduced synthetically?


What is a reasonable standard of care when an AI system is involved?


What does professional competence mean when lawyers and judges have access to machines capable of generating legal analysis?


What does accountability mean when an autonomous system acts across borders?


What does authenticity mean when almost any digital representation can be manufactured?


These are not questions for computer scientists alone. They concern legislators, judges, lawyers, regulators, businesses, technologists and international institutions.


They also cannot be postponed indefinitely while waiting for technology to stabilise.


Technology may never stabilise.


The Law Must Become More Adaptive


The central challenge is therefore not to create a single perfect AI law. There may never be one.


The more realistic objective is to construct a legal system capable of continually governing a technology that does not stand still.


That requires legislation establishing durable principles, regulators capable of responding quickly, technical standards capable of evolving, courts capable of interpreting new technological realities, professional bodies capable of establishing ethical rules and international institutions capable of coordinating cross-border responses.


Above all, legal systems must preserve the principle that technological sophistication does not eliminate accountability.


AI may become increasingly autonomous and capable of reasoning, planning and interacting with the world. But autonomy in operation does not automatically create legal responsibility. The law must still determine where responsibility rests.


ALI Perspective: From AI Regulation to AI Rule of Law


The emergence of artificial intelligence raises a question larger than technology regulation. It raises a question about the rule of law itself.


A society governed by law depends upon certain assumptions: facts can be established, evidence can be tested, decisions can be challenged, responsibility can be attributed and institutions can be held accountable.


Artificial intelligence does not necessarily destroy these principles. It does, however, place unprecedented pressure upon them.


A synthetic photograph challenges authenticity. A deepfake challenges identity. An AI hallucination challenges legal research. An autonomous agent challenges traditional concepts of agency. An opaque algorithm can challenge procedural fairness. An AI-generated decision can challenge accountability. An increasingly autonomous system can challenge the assumption that every consequential action begins and ends with a human decision-maker.


The future of AI law should therefore be understood not simply as regulation of technology, but as preservation of legal accountability in an age of increasingly intelligent machines.


The international debate should move beyond the simplistic question of whether AI is beneficial or dangerous. The more useful legal question is:


What rules are necessary to ensure that the benefits of artificial intelligence can be realised without allowing responsibility, rights and accountability to disappear into the technology?


There will be legitimate disagreement about how much regulation is appropriate, how quickly it should be introduced and which institutions should enforce it. Different constitutional systems will produce different answers. But the need for a serious legal framework is becoming increasingly difficult to ignore.


Artificial intelligence is moving from a tool that humans operate toward systems capable of performing complex sequences of tasks with limited intervention. Law cannot assume that tomorrow's technological environment will resemble yesterday's.


It must prepare for the possibility that it will not.


Conclusion: Governing the Intelligence We Create


Humanity has spent centuries developing laws to regulate human conduct. The AI age presents a new problem: we are creating systems capable of generating language, images, decisions, recommendations, code and increasingly autonomous actions at a speed that no human institution can match.


The question is not whether artificial intelligence should exist. It already does.


The question is whether legal institutions can evolve quickly enough to remain relevant as its capabilities expand.


The answer will probably not be found in one universal statute, nor in leaving every country entirely to itself. The emerging global experience suggests a more complex future: different national models, different regulatory philosophies and different levels of intervention, but potentially a shared foundation of human rights, accountability, transparency, safety, provenance, human oversight and effective remedies.


The European Union has demonstrated that comprehensive AI legislation is possible. China has demonstrated how synthetic-content regulation can be embedded within a broader technology-governance system. South Korea has created a dedicated AI statute. Japan has established a legislative and strategic framework. The United Kingdom has pursued principles-based regulation. The United States is developing a federal legislative framework. India is experimenting with a techno-legal, principle-based model. Australia is considering mandatory safeguards for high-risk AI. Brazil is developing a dedicated AI legal framework. At the international level, the United Nations has begun constructing an institutional process for global AI governance.


The next stage of the debate should therefore concern not whether AI will be regulated, but how regulation can remain effective while the technology continues to evolve.


The central principle should be neither fear of technology nor blind confidence in it.


It should be accountability.


An AI system may generate a photograph, but the law must still determine whether that photograph represents reality. It may generate a legal citation, but a court must establish whether the authority exists. It may make a recommendation, but a person affected by that recommendation should retain meaningful avenues of challenge where rights are at stake. An AI agent may perform an action, but the legal system must remain capable of identifying the human or institutional responsibility behind its deployment.


And when AI crosses borders, geography must not become a convenient escape from accountability.


The future of artificial intelligence will not be determined by technology alone. It will also be determined by the laws that societies choose to build around it.


The fundamental question facing governments, courts, lawyers, technology companies and international institutions is therefore no longer:

“Can artificial intelligence do this?”


The more important question is:

“If artificial intelligence can do this, what legal framework should govern it?”


That is the question the AI age is placing before the world.


And it is a question that law cannot afford to answer too late.

 


Comments


bottom of page